CVE-2026-80179: Python Jwcrypto Unbounded Jwt Split Dos

Unbounded string splitting on '.' when parsing compact JWE/JWS/JWT tokens can allow a remote attacker to trigger excessive memory allocation (MemoryError DoS) by providing numerous delimiter characters. Specify a maxsplit argument to split (e.g., `split('.', 5)`).

Provally CuratedPublic repositoryMediumMedium confidenceVerifiedApache-2.0Python
greprules fetch cve-2026-80179-python-jwcrypto-unbounded-jwt-split-dos --engine opengrep

Description

Unbounded string splitting on '.' when parsing compact JWE/JWS/JWT tokens can allow a remote attacker to trigger excessive memory allocation (MemoryError DoS) by providing numerous delimiter characters. Specify a maxsplit argument to split (e.g., `split('.', 5)`).